Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package syft for openSUSE:Factory checked in 
at 2025-11-21 16:54:59
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/syft (Old)
 and      /work/SRC/openSUSE:Factory/.syft.new.2061 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "syft"

Fri Nov 21 16:54:59 2025 rev:111 rq:1318795 version:1.38.0

Changes:
--------
--- /work/SRC/openSUSE:Factory/syft/syft.changes        2025-11-06 
18:17:41.862831916 +0100
+++ /work/SRC/openSUSE:Factory/.syft.new.2061/syft.changes      2025-11-21 
16:55:57.596543900 +0100
@@ -1,0 +2,53 @@
+Tue Nov 18 06:15:21 UTC 2025 - Johannes Kastl 
<[email protected]>
+
+- Update to version 1.38.0:
+  * Added Features
+    - add support for cataloging GGUF models [#4184 #4279 @spiffcs]
+    - Support scanning a list of CPEs [#3890 #4207 @chovanecadam]
+    - Syft does not detect Elixir binary on system [#4333 #4334
+      @rezmoss]
+  * Bug Fixes
+    - Support extras statements in Python PDM cataloger [#4352
+      @wagoodman]
+    - Preserve --from argument order [#4350 @wagoodman]
+    - SBOM generated by Syft 1.28 contains license elements missing
+      id or name (causing CycloneDX parser error) [#4363]
+    - empty PURL output in dependency snapshot format breaks
+      sbom-action [#4311]
+    - Interface includes constraint elements, can only be used in
+      type parameters [#4346]
+    - Upgrade github.com/nwaples/[email protected] to 2.2.1 [#4338]
+    - Upgrade to Golang 1.25.4 [#4341]
+  * Additional Changes
+    - migrate syft to use mholt/archives instead of anchore fork
+      [#4029 @Rupikz]
+    - Add license enrichment from pypi to python packages [#4295
+      @timols]
+    - license file search [#4327 @kzantow]
+  * Dependencies
+    - chore(deps): update anchore dependencies (#4374)
+    - chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.7.1
+      to 6.7.2 (#4372)
+    - chore(deps): bump golang.org/x/tools from 0.38.0 to 0.39.0
+      (#4364)
+    - chore(deps): update tools to latest versions (#4370)
+    - chore(deps): update tools to latest versions (#4365)
+    - chore(deps): bump github/codeql-action from 4.31.2 to 4.31.3
+      (#4366)
+    - chore(deps): update tools to latest versions (#4358)
+    - chore(deps): bump golang.org/x/mod from 0.29.0 to 0.30.0
+      (#4359)
+    - chore(deps): bump github.com/olekukonko/tablewriter from
+      1.0.9 to 1.1.1 (#4354)
+    - chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.7.0
+      to 6.7.1 (#4355)
+    - chore(deps): update tools to latest versions (#4347)
+    - chore(deps): bump github.com/opencontainers/selinux (#4349)
+    - chore(deps): bump golang.org/x/time from 0.12.0 to 0.14.0
+      (#4348)
+    - chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.6.9
+      to 6.7.0 (#4337)
+    - chore(deps): bump github.com/containerd/containerd from
+      1.7.28 to 1.7.29 (#4340)
+
+-------------------------------------------------------------------

Old:
----
  syft-1.37.0.obscpio

New:
----
  syft-1.38.0.obscpio

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ syft.spec ++++++
--- /var/tmp/diff_new_pack.kjFdnr/_old  2025-11-21 16:56:00.148651445 +0100
+++ /var/tmp/diff_new_pack.kjFdnr/_new  2025-11-21 16:56:00.148651445 +0100
@@ -17,7 +17,7 @@
 
 
 Name:           syft
-Version:        1.37.0
+Version:        1.38.0
 Release:        0
 Summary:        CLI tool and library for generating a Software Bill of 
Materials
 License:        Apache-2.0

++++++ _service ++++++
--- /var/tmp/diff_new_pack.kjFdnr/_old  2025-11-21 16:56:00.268656502 +0100
+++ /var/tmp/diff_new_pack.kjFdnr/_new  2025-11-21 16:56:00.276656839 +0100
@@ -3,7 +3,7 @@
     <param name="url">https://github.com/anchore/syft</param>
     <param name="scm">git</param>
     <param name="exclude">.git</param>
-    <param name="revision">v1.37.0</param>
+    <param name="revision">v1.38.0</param>
     <param name="versionformat">@PARENT_TAG@</param>
     <param name="versionrewrite-pattern">v(.*)</param>
     <param name="changesgenerate">enable</param>

++++++ _servicedata ++++++
--- /var/tmp/diff_new_pack.kjFdnr/_old  2025-11-21 16:56:00.328659030 +0100
+++ /var/tmp/diff_new_pack.kjFdnr/_new  2025-11-21 16:56:00.344659704 +0100
@@ -1,6 +1,6 @@
 <servicedata>
 <service name="tar_scm">
                 <param name="url">https://github.com/anchore/syft</param>
-              <param 
name="changesrevision">4c93394bc26c0bd649b58a6a1a9eb498f4847124</param></service></servicedata>
+              <param 
name="changesrevision">a033ae525f6c7ef937c6f49513e3403f07a1d6c0</param></service></servicedata>
 (No newline at EOF)
 

++++++ syft-1.37.0.obscpio -> syft-1.38.0.obscpio ++++++
++++ 27973 lines of diff (skipped)

++++++ syft.obsinfo ++++++
--- /var/tmp/diff_new_pack.kjFdnr/_old  2025-11-21 16:56:06.788931261 +0100
+++ /var/tmp/diff_new_pack.kjFdnr/_new  2025-11-21 16:56:06.848933790 +0100
@@ -1,5 +1,5 @@
 name: syft
-version: 1.37.0
-mtime: 1762191847
-commit: 4c93394bc26c0bd649b58a6a1a9eb498f4847124
+version: 1.38.0
+mtime: 1763399835
+commit: a033ae525f6c7ef937c6f49513e3403f07a1d6c0
 

++++++ vendor.tar.gz ++++++
/work/SRC/openSUSE:Factory/syft/vendor.tar.gz 
/work/SRC/openSUSE:Factory/.syft.new.2061/vendor.tar.gz differ: char 13, line 1

Reply via email to